]>
Commit | Line | Data |
---|---|---|
fa253735 | 1 | package PVE::Network::SDN::Controllers::EvpnPlugin; |
32602a38 AD |
2 | |
3 | use strict; | |
4 | use warnings; | |
cdf2c819 | 5 | |
074d270b AD |
6 | use PVE::INotify; |
7 | use PVE::JSONSchema qw(get_standard_option); | |
cdf2c819 TL |
8 | use PVE::Tools qw(run_command file_set_contents file_get_contents); |
9 | ||
10 | use PVE::Network::SDN::Controllers::Plugin; | |
1f543c5f | 11 | use PVE::Network::SDN::Zones::Plugin; |
f23633dc | 12 | use Net::IP; |
cdf2c819 | 13 | |
f5eabba0 | 14 | use base('PVE::Network::SDN::Controllers::Plugin'); |
32602a38 AD |
15 | |
16 | sub type { | |
fa253735 | 17 | return 'evpn'; |
8fb1ee7f AD |
18 | } |
19 | ||
32602a38 AD |
20 | sub properties { |
21 | return { | |
92526f0e TL |
22 | asn => { |
23 | type => 'integer', | |
24 | description => "autonomous system number", | |
25 | }, | |
26 | peers => { | |
27 | description => "peers address list.", | |
28 | type => 'string', format => 'ip-list' | |
29 | }, | |
32602a38 AD |
30 | }; |
31 | } | |
32 | ||
33 | sub options { | |
32602a38 | 34 | return { |
92526f0e TL |
35 | 'asn' => { optional => 0 }, |
36 | 'peers' => { optional => 0 }, | |
32602a38 AD |
37 | }; |
38 | } | |
39 | ||
40 | # Plugin implementation | |
8fb1ee7f | 41 | sub generate_controller_config { |
f23633dc | 42 | my ($class, $plugin_config, $controller_cfg, $id, $uplinks, $config) = @_; |
32602a38 | 43 | |
3caa7687 FG |
44 | my @peers; |
45 | @peers = PVE::Tools::split_list($plugin_config->{'peers'}) if $plugin_config->{'peers'}; | |
32602a38 | 46 | |
f23633dc AD |
47 | my $local_node = PVE::INotify::nodename(); |
48 | ||
074d270b | 49 | my $asn = $plugin_config->{asn}; |
f23633dc AD |
50 | my $ebgp = undef; |
51 | my $loopback = undef; | |
52 | my $autortas = undef; | |
53 | my $bgprouter = find_bgp_controller($local_node, $controller_cfg); | |
54 | if($bgprouter) { | |
55 | $ebgp = 1 if $plugin_config->{'asn'} ne $bgprouter->{asn}; | |
56 | $loopback = $bgprouter->{loopback} if $bgprouter->{loopback}; | |
57 | $asn = $bgprouter->{asn} if $bgprouter->{asn}; | |
58 | $autortas = $plugin_config->{'asn'} if $ebgp; | |
59 | } | |
074d270b AD |
60 | |
61 | return if !$asn; | |
32602a38 | 62 | |
92526f0e TL |
63 | my $bgp = $config->{frr}->{router}->{"bgp $asn"} //= {}; |
64 | ||
f23633dc | 65 | my ($ifaceip, $interface) = PVE::Network::SDN::Zones::Plugin::find_local_ip_interface_peers(\@peers, $loopback); |
32602a38 | 66 | |
f23633dc | 67 | my $remoteas = $ebgp ? "external" : $asn; |
17854295 | 68 | |
f23633dc | 69 | #global options |
92526f0e TL |
70 | my @controller_config = ( |
71 | "bgp router-id $ifaceip", | |
72 | "no bgp default ipv4-unicast", | |
73 | "coalesce-time 1000", | |
74 | ); | |
32602a38 | 75 | |
f23633dc AD |
76 | push(@{$bgp->{""}}, @controller_config) if keys %{$bgp} == 0; |
77 | ||
78 | @controller_config = (); | |
79 | ||
80 | #VTEP neighbors | |
81 | push @controller_config, "neighbor VTEP peer-group"; | |
82 | push @controller_config, "neighbor VTEP remote-as $remoteas"; | |
83 | push @controller_config, "neighbor VTEP bfd"; | |
84 | ||
85 | if($ebgp && $loopback) { | |
86 | push @controller_config, "neighbor VTEP ebgp-multihop 10"; | |
87 | push @controller_config, "neighbor VTEP update-source $loopback"; | |
88 | } | |
89 | ||
90 | # VTEP peers | |
32602a38 AD |
91 | foreach my $address (@peers) { |
92 | next if $address eq $ifaceip; | |
f23633dc | 93 | push @controller_config, "neighbor $address peer-group VTEP"; |
7d35eaf5 | 94 | } |
074d270b | 95 | |
92526f0e | 96 | push(@{$bgp->{""}}, @controller_config); |
074d270b | 97 | |
f23633dc | 98 | # address-family l2vpn |
56cdcac9 | 99 | @controller_config = (); |
f23633dc | 100 | push @controller_config, "neighbor VTEP activate"; |
56cdcac9 | 101 | push @controller_config, "advertise-all-vni"; |
f23633dc | 102 | push @controller_config, "autort as $autortas" if $autortas; |
92526f0e | 103 | push(@{$bgp->{"address-family"}->{"l2vpn evpn"}}, @controller_config); |
32602a38 AD |
104 | |
105 | return $config; | |
106 | } | |
107 | ||
56cdcac9 | 108 | sub generate_controller_zone_config { |
f23633dc AD |
109 | my ($class, $plugin_config, $controller, $controller_cfg, $id, $uplinks, $config) = @_; |
110 | ||
111 | my $local_node = PVE::INotify::nodename(); | |
0589eb09 | 112 | |
1de0abc0 | 113 | my $vrf = "vrf_$id"; |
0589eb09 | 114 | my $vrfvxlan = $plugin_config->{'vrf-vxlan'}; |
f23633dc AD |
115 | my $exitnodes = $plugin_config->{'exitnodes'}; |
116 | ||
56cdcac9 | 117 | my $asn = $controller->{asn}; |
f23633dc AD |
118 | my $ebgp = undef; |
119 | my $loopback = undef; | |
120 | my $autortas = undef; | |
121 | my $bgprouter = find_bgp_controller($local_node, $controller_cfg); | |
122 | if($bgprouter) { | |
123 | $ebgp = 1 if $controller->{'asn'} ne $bgprouter->{asn}; | |
124 | $loopback = $bgprouter->{loopback} if $bgprouter->{loopback}; | |
125 | $asn = $bgprouter->{asn} if $bgprouter->{asn}; | |
126 | $autortas = $controller->{'asn'} if $ebgp; | |
127 | } | |
0589eb09 AD |
128 | |
129 | return if !$vrf || !$vrfvxlan || !$asn; | |
130 | ||
92526f0e | 131 | # vrf |
56cdcac9 AD |
132 | my @controller_config = (); |
133 | push @controller_config, "vni $vrfvxlan"; | |
134 | push(@{$config->{frr}->{vrf}->{"$vrf"}}, @controller_config); | |
0589eb09 | 135 | |
f23633dc AD |
136 | #main vrf router |
137 | @controller_config = (); | |
138 | push @controller_config, "no bgp ebgp-requires-policy" if $ebgp; | |
139 | # push @controller_config, "!"; | |
140 | push(@{$config->{frr}->{router}->{"bgp $asn vrf $vrf"}->{""}}, @controller_config); | |
659c27c2 | 141 | |
f23633dc AD |
142 | if ($autortas) { |
143 | push(@{$config->{frr}->{router}->{"bgp $asn vrf $vrf"}->{"address-family"}->{"l2vpn evpn"}}, "route-target import $autortas:$vrfvxlan"); | |
144 | push(@{$config->{frr}->{router}->{"bgp $asn vrf $vrf"}->{"address-family"}->{"l2vpn evpn"}}, "route-target export $autortas:$vrfvxlan"); | |
145 | } | |
0589eb09 | 146 | |
b634e577 AD |
147 | my $is_gateway = $exitnodes->{$local_node}; |
148 | ||
0589eb09 AD |
149 | if ($is_gateway) { |
150 | ||
56cdcac9 | 151 | @controller_config = (); |
0589eb09 | 152 | #import /32 routes of evpn network from vrf1 to default vrf (for packet return) |
56cdcac9 AD |
153 | push @controller_config, "import vrf $vrf"; |
154 | push(@{$config->{frr}->{router}->{"bgp $asn"}->{"address-family"}->{"ipv4 unicast"}}, @controller_config); | |
155 | push(@{$config->{frr}->{router}->{"bgp $asn"}->{"address-family"}->{"ipv6 unicast"}}, @controller_config); | |
0589eb09 | 156 | |
56cdcac9 | 157 | @controller_config = (); |
0589eb09 | 158 | #redistribute connected to be able to route to local vms on the gateway |
56cdcac9 AD |
159 | push @controller_config, "redistribute connected"; |
160 | push(@{$config->{frr}->{router}->{"bgp $asn vrf $vrf"}->{"address-family"}->{"ipv4 unicast"}}, @controller_config); | |
161 | push(@{$config->{frr}->{router}->{"bgp $asn vrf $vrf"}->{"address-family"}->{"ipv6 unicast"}}, @controller_config); | |
0589eb09 | 162 | |
56cdcac9 | 163 | @controller_config = (); |
0589eb09 | 164 | #add default originate to announce 0.0.0.0/0 type5 route in evpn |
56cdcac9 AD |
165 | push @controller_config, "default-originate ipv4"; |
166 | push @controller_config, "default-originate ipv6"; | |
167 | push(@{$config->{frr}->{router}->{"bgp $asn vrf $vrf"}->{"address-family"}->{"l2vpn evpn"}}, @controller_config); | |
0589eb09 AD |
168 | } |
169 | ||
170 | return $config; | |
171 | } | |
172 | ||
32602a38 | 173 | sub on_delete_hook { |
56cdcac9 | 174 | my ($class, $controllerid, $zone_cfg) = @_; |
32602a38 | 175 | |
56cdcac9 AD |
176 | # verify that zone is associated to this controller |
177 | foreach my $id (keys %{$zone_cfg->{ids}}) { | |
92526f0e TL |
178 | my $zone = $zone_cfg->{ids}->{$id}; |
179 | die "controller $controllerid is used by $id" | |
180 | if (defined($zone->{controller}) && $zone->{controller} eq $controllerid); | |
5bda8607 | 181 | } |
32602a38 AD |
182 | } |
183 | ||
184 | sub on_update_hook { | |
56cdcac9 | 185 | my ($class, $controllerid, $controller_cfg) = @_; |
5bda8607 | 186 | |
c7bb4ac5 AD |
187 | # we can only have 1 evpn controller / 1 asn by server |
188 | ||
f23633dc | 189 | my $controllernb = 0; |
56cdcac9 AD |
190 | foreach my $id (keys %{$controller_cfg->{ids}}) { |
191 | next if $id eq $controllerid; | |
92526f0e | 192 | my $controller = $controller_cfg->{ids}->{$id}; |
f23633dc AD |
193 | next if $controller->{type} ne "evpn"; |
194 | $controllernb++; | |
195 | die "only 1 global evpn controller can be defined" if $controllernb > 1; | |
196 | } | |
197 | } | |
198 | ||
199 | sub find_bgp_controller { | |
200 | my ($nodename, $controller_cfg) = @_; | |
201 | ||
202 | my $controller = undef; | |
203 | foreach my $id (keys %{$controller_cfg->{ids}}) { | |
204 | $controller = $controller_cfg->{ids}->{$id}; | |
205 | next if $controller->{type} ne 'bgp'; | |
206 | next if $controller->{node} ne $nodename; | |
207 | last; | |
5bda8607 | 208 | } |
f23633dc AD |
209 | |
210 | return $controller; | |
32602a38 AD |
211 | } |
212 | ||
f23633dc | 213 | |
8fb1ee7f AD |
214 | sub sort_frr_config { |
215 | my $order = {}; | |
216 | $order->{''} = 0; | |
217 | $order->{'vrf'} = 1; | |
218 | $order->{'ipv4 unicast'} = 1; | |
219 | $order->{'ipv6 unicast'} = 2; | |
220 | $order->{'l2vpn evpn'} = 3; | |
221 | ||
222 | my $a_val = 100; | |
223 | my $b_val = 100; | |
224 | ||
225 | $a_val = $order->{$a} if defined($order->{$a}); | |
226 | $b_val = $order->{$b} if defined($order->{$b}); | |
227 | ||
92526f0e | 228 | if ($a =~ /bgp (\d+)$/) { |
8fb1ee7f AD |
229 | $a_val = 2; |
230 | } | |
231 | ||
92526f0e | 232 | if ($b =~ /bgp (\d+)$/) { |
8fb1ee7f AD |
233 | $b_val = 2; |
234 | } | |
235 | ||
236 | return $a_val <=> $b_val; | |
237 | } | |
238 | ||
239 | sub generate_frr_recurse{ | |
240 | my ($final_config, $content, $parentkey, $level) = @_; | |
241 | ||
242 | my $keylist = {}; | |
243 | $keylist->{vrf} = 1; | |
244 | $keylist->{'address-family'} = 1; | |
245 | $keylist->{router} = 1; | |
246 | ||
247 | my $exitkeylist = {}; | |
248 | $exitkeylist->{vrf} = 1; | |
249 | $exitkeylist->{'address-family'} = 1; | |
250 | ||
92526f0e | 251 | # FIXME: make this generic |
8fb1ee7f | 252 | my $paddinglevel = undef; |
92526f0e TL |
253 | if ($level == 1 || $level == 2) { |
254 | $paddinglevel = $level - 1; | |
8fb1ee7f | 255 | } elsif ($level == 3 || $level == 4) { |
92526f0e | 256 | $paddinglevel = $level - 2; |
8fb1ee7f AD |
257 | } |
258 | ||
259 | my $padding = ""; | |
260 | $padding = ' ' x ($paddinglevel) if $paddinglevel; | |
261 | ||
92526f0e | 262 | if (ref $content eq 'HASH') { |
8fb1ee7f AD |
263 | foreach my $key (sort sort_frr_config keys %$content) { |
264 | if ($parentkey && defined($keylist->{$parentkey})) { | |
92526f0e TL |
265 | push @{$final_config}, $padding."!"; |
266 | push @{$final_config}, $padding."$parentkey $key"; | |
267 | } elsif ($key ne '' && !defined($keylist->{$key})) { | |
268 | push @{$final_config}, $padding."$key"; | |
8fb1ee7f AD |
269 | } |
270 | ||
271 | my $option = $content->{$key}; | |
272 | generate_frr_recurse($final_config, $option, $key, $level+1); | |
273 | ||
274 | push @{$final_config}, $padding."exit-$parentkey" if $parentkey && defined($exitkeylist->{$parentkey}); | |
275 | } | |
276 | } | |
32602a38 | 277 | |
8fb1ee7f | 278 | if (ref $content eq 'ARRAY') { |
92526f0e | 279 | push @{$final_config}, map { $padding . "$_" } @$content; |
8fb1ee7f AD |
280 | } |
281 | } | |
282 | ||
283 | sub write_controller_config { | |
284 | my ($class, $plugin_config, $config) = @_; | |
285 | ||
659c27c2 AD |
286 | my $nodename = PVE::INotify::nodename(); |
287 | ||
8fb1ee7f AD |
288 | my $final_config = []; |
289 | push @{$final_config}, "log syslog informational"; | |
659c27c2 AD |
290 | push @{$final_config}, "ip forwarding"; |
291 | push @{$final_config}, "ipv6 forwarding"; | |
67a0f815 | 292 | push @{$final_config}, "frr defaults datacenter"; |
659c27c2 AD |
293 | push @{$final_config}, "service integrated-vtysh-config"; |
294 | push @{$final_config}, "hostname $nodename"; | |
8fb1ee7f AD |
295 | push @{$final_config}, "!"; |
296 | ||
0d1ab7dc | 297 | if (-e "/etc/frr/frr.conf.local") { |
0d1ab7dc AD |
298 | generate_frr_recurse($final_config, $config->{frr}->{vrf}, "vrf", 1); |
299 | push @{$final_config}, "!"; | |
300 | ||
cdf2c819 TL |
301 | my $local_conf = file_get_contents("/etc/frr/frr.conf.local"); |
302 | chomp ($local_conf); | |
303 | push @{$final_config}, $local_conf; | |
0d1ab7dc AD |
304 | } else { |
305 | generate_frr_recurse($final_config, $config->{frr}, undef, 0); | |
306 | } | |
8fb1ee7f AD |
307 | |
308 | push @{$final_config}, "!"; | |
309 | push @{$final_config}, "line vty"; | |
310 | push @{$final_config}, "!"; | |
311 | ||
312 | my $rawconfig = join("\n", @{$final_config}); | |
313 | ||
8fb1ee7f AD |
314 | return if !$rawconfig; |
315 | return if !-d "/etc/frr"; | |
316 | ||
cdf2c819 | 317 | file_set_contents("/etc/frr/frr.conf", $rawconfig); |
8fb1ee7f AD |
318 | } |
319 | ||
fa609bdd AD |
320 | sub reload_controller { |
321 | my ($class) = @_; | |
322 | ||
323 | my $conf_file = "/etc/frr/frr.conf"; | |
659c27c2 AD |
324 | my $bin_path = "/usr/lib/frr/frr-reload.py"; |
325 | ||
326 | if (!-e $bin_path) { | |
327 | warn "missing $bin_path. Please install frr-pythontools package"; | |
328 | return; | |
329 | } | |
fa609bdd AD |
330 | |
331 | my $err = sub { | |
332 | my $line = shift; | |
659c27c2 AD |
333 | if ($line =~ /ERROR:/) { |
334 | warn "$line \n"; | |
fa609bdd AD |
335 | } |
336 | }; | |
337 | ||
338 | if (-e $conf_file && -e $bin_path) { | |
cdf2c819 | 339 | run_command([$bin_path, '--stdout', '--reload', $conf_file], outfunc => {}, errfunc => $err); |
fa609bdd AD |
340 | } |
341 | } | |
342 | ||
8fb1ee7f | 343 | 1; |
32602a38 | 344 | |
0589eb09 | 345 |